Last updated: 9 September 2026 · Contact: support@sageschema.com
1. Who is responsible
klaryn.ai is the product name of the service available at sageschema.com (and, after the domain cutover, klaryn.ai). For the purposes of the GDPR, the operator of this service is the controller of personal data processed through the site and the workspace, except where we act as a processor for an agency that invites its own clients into a shared discovery.
To exercise your rights or ask a privacy question, email support@sageschema.com. See also the imprint.
2. What this service does
klaryn.ai runs an AI-led discovery interview and generates HubSpot planning documents (an Ideal Customer Profile, an implementation blueprint, a click-by-click runbook, and optional add-ons). Agencies can white-label discovery for their clients. Paid features are billed through Stripe.
3. Data we process
Account
When you register we store your name, email address, and an HMAC-hashed one-time passcode — we never store a reusable password. After login we keep a session in an httpOnly cookie. You can request deletion of the account; that also removes associated workspace data we can reach (see §8).
Discovery and documents
Interview answers, uploaded context, generated Markdown documents, job state, and related metadata are stored so you can resume work and download deliverables. If you put a project in an encrypted vault, the contents are encrypted in your browser with AES-256 before they are stored. We hold ciphertext. We cannot open a vault without the password, which never leaves your device.
Service booking
If you use the HubSpot RevOps booking form, we process the name, email, company, engagement type and note you submit so we can reply and scope the work. That is a request you made (Art. 6(1)(b)). We keep the message until the conversation is finished, then as ordinary correspondence.
Support requests
If you use the support form, we process the name, email, topic and message you submit so we can reply. That is a request you made (Art. 6(1)(b)), or our legitimate interest in helping you use the service (Art. 6(1)(f)). We keep the message until the conversation is finished, then as ordinary correspondence. You can still email support@sageschema.com instead.
Billing
Payments are handled by Stripe. We receive the minimum we need to entitle your account (customer id, subscription or payment status, the product purchased). Card numbers do not touch our servers. Stripe’s own privacy notice applies to the payment flow.
Agency sharing and custom domains
If you send a discovery link, we process the guest’s answers on behalf of your workspace. Branding settings (logo, colours, company name, support email, custom hostname) are stored so the share page can render. A custom domain that points at us may receive a TLS certificate so the hostname can be served over HTTPS.
Technical logs
We keep operational logs (errors, deploy and health checks, coarse usage for generation) to run and secure the service. Access logs on the reverse proxy record IP address, user agent and the requested path for a limited period.
Cookies and similar storage
We only set cookies that are required to run the service. Details, names and lifetimes are on the Cookie Policy.
4. Why we process it (legal bases)
- Contract (Art. 6(1)(b) GDPR) — to create your account, run discovery, generate documents, take payment and provide support.
- Legitimate interests (Art. 6(1)(f)) — to keep the service secure, debug failures, prevent abuse, and understand whether generation completed. You may object; see §8.
- Legal obligation (Art. 6(1)(c)) — tax and accounting records for paid invoices, and to respond to lawful requests.
- Consent — only where we ask for it. We do not use advertising or analytics cookies, so we do not show a marketing-cookie banner.
5. Who we share it with
We do not sell personal data. We use processors who only see what they need to provide their part of the service:
- Hosting — the application and databases are hosted in Germany, in the EU.
- Anthropic — discovery chat and document generation are produced by Anthropic’s Claude models. Prompts include the interview and the context needed to write the document. We do not use your data to train our own models, and we do not permit it to be used to train foundation models on our side. Anthropic’s terms for API customers apply to that processing.
- Stripe — checkout, invoices, the customer billing portal and subscription state.
- Email delivery — one-time login codes, vault invitations, transactional notices, RevOps booking requests and support-form messages are sent over SMTP (currently Google Workspace / Gmail).
- HubSpot knowledge index — a separate sidecar searches a local index of HubSpot’s public documentation. Customer interview content is not written into that index. Embedding of HubSpot’s public docs uses Google’s Gemini API on our side; that is documentation text, not your CRM data.
Agencies who invite a client share that client’s answers with the agency workspace by design. White-label pages are still served by us.
6. International transfers
Hosting is in the EU. Some processors (notably Anthropic and Stripe) may process data in the United States. Where GDPR requires a transfer tool, we rely on the processor’s Standard Contractual Clauses and supplementary measures they publish. Generating a document necessarily sends the relevant prompt to the model provider.
7. How long we keep it
- Account and workspace data — until you delete the account or the individual documents, plus a short backup window on our side.
- Encrypted vault ciphertext — until the vault is deleted. If you lose the password, we cannot recover the contents; deletion still removes the ciphertext we hold.
- Session cookie — 30 days of inactivity, or when you log out.
- Visitor id cookie — up to 12 months, refreshed while you keep using the site.
- Billing records — as required for tax (typically several years).
- Security logs — rotated; not used as a second copy of your documents.
8. Your rights
If GDPR applies to you, you can ask us to access, rectify, erase, restrict or port your personal data, and to object to processing based on legitimate interests. You may lodge a complaint with your local supervisory authority — in Germany, that is a State Commissioner for Data Protection, or the Federal Commissioner (BfDI).
You can delete discoveries and documents from the workspace. For a full account erasure, email support@sageschema.com from the address on the account. Encrypted vault contents are unreadable to us; we can delete the ciphertext, not reconstruct the plaintext.
9. Children
The service is for business users. It is not directed at children under 16, and we do not knowingly collect their data.
10. Changes
If we change this policy in a material way, we will update the date above and, where the change affects an existing account, notify the email on the account. Continued use after the update is acceptance of the revised policy.
Related: Terms of Service · Cookie Policy · Disclaimer · Imprint